-
Notifications
You must be signed in to change notification settings - Fork 24
fix: update dependabot.yml to add applies-to
#345
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
I am not sure how exclude-patterns works with group. But it seems `applies-to: "security-updates"` seems to work from this example https://github.com/hashicorp/golang-lru/blob/1ecdc13547b564bf736db9161ed89f1864010108/.github/dependabot.yml#L19-L36
applies-to
See GH tutorial about optimizing the number of PRs submitted. There's also an example in there that uses a And also, the config docs. I think But I'm willing to try this. I still suspect the patterns are not actually grouping the dependencies like expected. |
Interesting option.
Let's try this first, then try cooldown if it does not work well. |
|
Caution Review failedThe pull request is closed. WalkthroughDependabot configuration in .github/dependabot.yml was modified for the uv package ecosystem: in the dev and docs groups, the update-types array was removed and replaced with applies-to: "security-updates", constraining those groups to security updates only. Changes
Estimated code review effort🎯 2 (Simple) | ⏱️ ~10 minutes Suggested labels
Suggested reviewers
✨ Finishing touches🧪 Generate unit tests
📜 Recent review detailsConfiguration used: CodeRabbit UI Review profile: CHILL Plan: Pro 📒 Files selected for processing (1)
Tip 👮 Agentic pre-merge checks are now available in preview!Pro plan users can now enable pre-merge checks in their settings to enforce checklists before merging PRs.
Please see the documentation for more information. Example: reviews:
pre_merge_checks:
custom_checks:
- name: "Undocumented Breaking Changes"
mode: "warning"
instructions: |
Pass/fail criteria: All breaking changes to public APIs, CLI flags, environment variables, configuration keys, database schemas, or HTTP/GraphQL endpoints must be documented in the "Breaking Change" section of the PR description and in CHANGELOG.md. Exclude purely internal or private changes (e.g., code not exported from package entry points or explicitly marked as internal).Please share your feedback with us on this Discord post. Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
I am not sure how
exclude-patternsworks with a group, but it seemsapplies-to: "security-updates"seems to work from this examplehttps://github.com/hashicorp/golang-lru/blob/1ecdc13547b564bf736db9161ed89f1864010108/.github/dependabot.yml#L19-L36
closes #337
Summary by CodeRabbit